Security + Trust Center
What your security team needs, documented.
Certifications + Controls
The compliance posture vendor review teams ask about. Evidence available on request.
SOC 2 Type II controls (certification in progress)
Controls implemented across security, availability, confidentiality, and privacy. Audit window opens Q3 2026; Type II attestation report will be available on request under NDA once issued.
CCPA registered data broker
Registered with the California Privacy Protection Agency. Registration number available on request.
IAB TCF v2.2 compliant
Consent signals captured and propagated per the Transparency and Consent Framework. GVL ID pending registration.
FCRA firewall
Zero FCRA-regulated fields stored or distributed — no credit score, bankruptcy, employment history, criminal record, or payment history. No buyer certification unlocks these.
CA DELETE Act ready
45-day deletion workflow with record-level deletion resilience classification. Deletion cascades through sub-processors and is attested per cycle.
GDPR lawful basis per record
B2B signals under Art. 6(1)(f) legitimate interests; consumer signals under Art. 6(1)(a) explicit consent. Consent mode tagged and carried with every record.
Deletion-resilience breakdown
Headline claim, sampled live from the production signal inventory.
Deletion-resilience breakdown is recomputing.
DELETE Act cascade performance
Turning the CA DELETE Act into a live metric — not a promise.
DELETE Act cascade meter is temporarily unavailable.
Non-deletable supply — 90-day trend
Non-deletable supply % over the last 90 days. Positive trend = moat strengthening.
Enforced at the record level
Every signal passes through our compliance pipeline before delivery.
Consent, identity hashing, suppression checks, FCRA filtering, and audit logging are all enforced at the record level.
Records that fail any check are dropped, never delivered.
Documents Available Under NDA
Email [email protected] to request any of the following. We'll send a mutual NDA and route to the right document.
Data Processing Agreement
Standard DPA covers most engagements. Negotiable custom terms for enterprise legal.
Sub-processor list with roles
Full sub-processor inventory including AWS, Supabase, Anthropic, Firecrawl, Hunter, Lusha, Prospeo, and others — with the role each plays in the pipeline.
Deletion cascade documentation
How deletion requests propagate through primary stores, caches, sub-processors, and delivered buyer streams.
SOC 2 report
Controls implemented and seeded in evidence log; Type II audit window opens Q3 2026. Attestation report shareable under NDA once issued.
Privacy impact assessment template
Pre-filled PIA template covering the signal refinery data flow for your DPO or privacy counsel.
Incident response runbook summary
Detection, containment, notification, and post-incident review timelines — summary available pre-NDA, full runbook under NDA.
Report a vulnerability
We respond to vulnerability reports within 24 hours.
[email protected]